Page 1 of 1

Were we hacked?

PostPosted: August 25th, 2018, 3:24 pm
by CraigKressel
I went to the site and it loaded up with Cialis ads on my phone. No I don't have a virus on my phone either.

Re: Were we hacked?

PostPosted: August 25th, 2018, 10:05 pm
by FuckESPNdotCOM
CraigKressel wrote:I went to the site and it loaded up with Cialis ads on my phone. No I don't have a virus on my phone either.

Doubtful. Who would want to hack a site with 10 unique visitors per day?

Possibilities include:
-sellular1 added a new revenue stream to pay for the site (doubtful)
-You have some malware on your phone, be it a hijacker or some tracking and Javascript exploits (likely)
-You typed in the URI wrong (possible) and went to a different site.

Ads and bullshit are the reason I have a Javascript whitelist for domains. It works pretty well at stopping BS like you describe. I rarely have it turned on when I look at this site.


But hey, all the more reason for the admins to switch to https like I brought up a month or so ago.

Re: Were we hacked?

PostPosted: August 25th, 2018, 10:24 pm
by CraigKressel
FuckESPNdotCOM wrote:
CraigKressel wrote:I went to the site and it loaded up with Cialis ads on my phone. No I don't have a virus on my phone either.

Doubtful. Who would want to hack a site with 10 unique visitors per day?

Possibilities include:
-sellular1 added a new revenue stream to pay for the site (doubtful)
-You have some malware on your phone, be it a hijacker or some tracking and Javascript exploits (likely)
-You typed in the URI wrong (possible) and went to a different site.

Ads and bullshit are the reason I have a Javascript whitelist for domains. It works pretty well at stopping BS like you describe. I rarely have it turned on when I look at this site.


But hey, all the more reason for the admins to switch to https like I brought up a month or so ago.


Um people with bots looking for exploits on PHP BB, Wordpress, opencart, magento etc. Its not like they manually seek out websites they have bots that find old versions.

Re: Were we hacked?

PostPosted: August 25th, 2018, 10:28 pm
by CraigKressel
https://productforums.google.com/forum/ ... UwgyzROra0 this is what happens.

It is not my phone, trust me its the website.

Re: Were we hacked?

PostPosted: August 25th, 2018, 10:31 pm
by CraigKressel

Re: Were we hacked?

PostPosted: August 26th, 2018, 12:59 am
by FuckESPNdotCOM
CraigKressel wrote:https://www.google.com/search?q=site%3Ahttp%3A%2F%2Fthesportshole.com%2Fboard%2F&ie=utf-8&oe=utf-8&client=firefox-b-1

The site is hacked.

lol. Why are you searching for this site on Google? It manipulated crawler output. Interesting.

The site displays fine, though. No ads for me. :2thumbs And a regular Google search without using the site: prefix doesn't show that crap, BTW.

*cough* Needs moar HTTPS *cough*

Re: Were we hacked?

PostPosted: August 26th, 2018, 1:13 am
by Muck FcDisney
R.I.P. OP's dick.

Re: Were we hacked?

PostPosted: August 26th, 2018, 3:18 am
by CraigKressel
FuckESPNdotCOM wrote:
CraigKressel wrote:https://www.google.com/search?q=site%3Ahttp%3A%2F%2Fthesportshole.com%2Fboard%2F&ie=utf-8&oe=utf-8&client=firefox-b-1

The site is hacked.

lol. Why are you searching for this site on Google? It manipulated crawler output. Interesting.

The site displays fine, though. No ads for me. :2thumbs And a regular Google search without using the site: prefix doesn't show that crap, BTW.

*cough* Needs moar HTTPS *cough*


I was searching so that you can see the hacked pages.

Re: Were we hacked?

PostPosted: August 26th, 2018, 3:19 am
by CraigKressel
FuckESPNdotCOM wrote:
CraigKressel wrote:https://www.google.com/search?q=site%3Ahttp%3A%2F%2Fthesportshole.com%2Fboard%2F&ie=utf-8&oe=utf-8&client=firefox-b-1

The site is hacked.

lol. Why are you searching for this site on Google? It manipulated crawler output. Interesting.

The site displays fine, though. No ads for me. :2thumbs And a regular Google search without using the site: prefix doesn't show that crap, BTW.

*cough* Needs moar HTTPS *cough*


Thats because whatever device / browser combo you are using it is not redirecting to the hacked pages on for whatever reason.

Re: Were we hacked?

PostPosted: August 27th, 2018, 9:08 pm
by CraigKressel
sellular1 wrote:This shitty site still works for me :moon


Yea but the site is hacked, I showed it on google. you can see for yourself.

Re: Were we hacked?

PostPosted: August 27th, 2018, 9:30 pm
by bigbluebazooka
sellular1 wrote:This shitty site still works for me :moon

:iwaf

Re: Were we hacked?

PostPosted: August 28th, 2018, 2:23 am
by CraigKressel
bigbluebazooka wrote:
sellular1 wrote:This shitty site still works for me :moon

:iwaf


It will be blacklisted on google before long so much for new users, also it could be stealing your login info when you login and it will probably only get worse if someone doesnt fix it.

Re: Were we hacked?

PostPosted: August 28th, 2018, 3:29 pm
by FuckESPNdotCOM
CraigKressel wrote:
bigbluebazooka wrote:
sellular1 wrote:This shitty site still works for me :moon

:iwaf


It will be blacklisted on google before long so much for new users, also it could be stealing your login info when you login and it will probably only get worse if someone doesnt fix it.

I agree with Craig on this one. That's how bad this is.

The security needs to be addressed. Even if the site is working for us, it doesn't mean it wasn't compromised. We need an admin to fix the .htaccess file and add a basic https service for the site. It's not hard and like Craig said, it means the passwords are vulnerable, as I said several weeks ago.

http://www.howto-expert.com/how-to-get- ... r-website/

You can get a self-signed cert for free.

https://serversforhackers.com/c/self-si ... rtificates

Who usually takes care of this stuff? Canes_Knights?

Re: Were we hacked?

PostPosted: August 28th, 2018, 5:20 pm
by Muck FcDisney
sellular1 wrote:Don't keep telling me about the problem, fix the damn problem.


Everyone's a mod now! :newnana

Re: Were we hacked?

PostPosted: August 28th, 2018, 7:30 pm
by CraigKressel
sellular1 wrote:Don't keep telling me about the problem, fix the damn problem.


Uh how I don't have access to it.

Re: Were we hacked?

PostPosted: August 28th, 2018, 8:09 pm
by Muck FcDisney
CraigKressel wrote:
sellular1 wrote:Don't keep telling me about the problem, fix the damn problem.


Uh how I don't have access to it.


We're working on it, trust me. We've only known about the issue since December.

Once the advisory panel completes their review, our consulting firm will take a look at it. Then we can bid it out to independent contractors and then review those bids. It's only a matter of time.

Re: Were we hacked?

PostPosted: August 28th, 2018, 10:07 pm
by JdPat04
Muck FcDisney wrote:
CraigKressel wrote:
sellular1 wrote:Don't keep telling me about the problem, fix the damn problem.


Uh how I don't have access to it.


We're working on it, trust me. We've only known about the issue since December.

Once the advisory panel completes their review, our consulting firm will take a look at it. Then we can bid it out to independent contractors and then review those bids. It's only a matter of time.



Can’t we just wipe it all clean?

[ img ]

Re: Were we hacked?

PostPosted: August 28th, 2018, 11:38 pm
by CraigKressel
JdPat04 wrote:
Muck FcDisney wrote:
CraigKressel wrote:
sellular1 wrote:Don't keep telling me about the problem, fix the damn problem.


Uh how I don't have access to it.


We're working on it, trust me. We've only known about the issue since December.

Once the advisory panel completes their review, our consulting firm will take a look at it. Then we can bid it out to independent contractors and then review those bids. It's only a matter of time.



Can’t we just wipe it all clean?

[ img ]


You mean like with a cloth?